Search papers, labs, and topics across Lattice.
This paper introduces CryptoProver, an AI-driven system that automates the verification of cryptographic libraries by synthesizing internal specifications and generating proofs from high-level API contracts. The significance lies in its ability to independently verify critical implementations, such as curve25519-dalek and the previously unverified chacha20 against established specifications, without altering the executable code. CryptoProver achieves this in a cost-effective manner, completing the verification process in 11.4 hours at a cost of approximately $466, highlighting its potential to enhance the reliability of cryptographic infrastructure used in widely adopted applications like Signal.
CryptoProver can independently verify cryptographic libraries in under 12 hours, ensuring the integrity of critical code without altering its execution.
Cryptographic code is critical infrastructure that must be correct, yet formally verifying production libraries remains difficult. Existing language-model proof systems solve isolated obligations with specifications and premises already given, leaving production-library verification unresolved. We present CryptoProver, an AI-based system that synthesizes internal specifications and Verus-checked proofs from high-level API contracts. Without changing executable code, CryptoProver constructs a new independent proof of curve25519-dalek and verifies RustCrypto's previously unverified chacha20 implementation against an RFC 8439 specification. These cryptographic lineages underpin deployed systems including Signal and Shadowsocks; Signal has an estimated 218M global downloads. The independent, human-led curve25519-dalek verification was developed publicly over eight months by five main contributors. Given the API contracts and a fixed trusted library of field specifications, arithmetic facts, axioms, and vstd, CryptoProver synthesizes the internal specifications and proofs in 11.4 hours with USD 466.99 in recorded API cost. CryptoProver follows a trust-first design principle: mechanical gates reject specification weakening, invented axioms, and cross-module breakage, while isolation blocks reference proof retrieval, including from git history.